Impact
A low‑privileged user can obtain an administrator API key and use it to perform actions that require administrative privileges. The flaw exploits improper privilege management, allowing the attacker to elevate their access level within ManageEngine Applications Manager.
Affected Systems
Zohocorp ManageEngine Applications Manager versions 182000 and earlier are vulnerable. Users of these versions should identify whether they run one of these releases.
Risk and Exploitability
The CVSS score of 8.8 signifies a high severity vulnerability. No EPSS score is available to gauge current exploit likelihood, and it is not listed in the CISA KEV catalog. The attack is likely carried out through the web application interfaces using a credentialed, low‑privileged account; the attacker can bypass privilege checks to obtain the API key and then perform privileged actions.
OpenCVE Enrichment